Miscellaneous topics that do not fit into specific categories.
BitLocker (or automatic device encryption) is what showed the blue recovery screen. When BitLocker is enabled, it cannot be “turned off” from that screen; the drive must first be successfully unlocked with a valid recovery key. Without the recovery key, the data on the drive is designed to be unrecoverable.
Since a previous university was able to provide a working recovery key, the steps to prevent this in the future are:
- Back up the recovery key immediately
After signing in successfully:- Open Start and type Manage BitLocker.
- Select Manage BitLocker to open BitLocker Drive Encryption.
- For the operating system drive, choose Back up your recovery key and save it to a safe location (for example, a Microsoft account, another device, or a printed copy).
If the device uses automatic device encryption instead of full BitLocker UI, follow the guidance in Back up your BitLocker recovery key from the BitLocker overview article.
- Check whether BitLocker or device encryption is actually on
- Sign in with an administrator account.
- Open Start → type BitLocker → select Manage BitLocker.
- If Manage BitLocker is not listed, the edition of Windows might not support BitLocker Drive Encryption, or only automatic device encryption is in use.
- If the BitLocker control panel opens, check the Operating system drive section to see if it shows BitLocker on.
- Turn off BitLocker Drive Encryption (if available)
If the BitLocker Drive Encryption control panel shows the OS drive as encrypted:- Next to the OS drive, select Turn off BitLocker.
- Confirm when prompted.
- The drive will decrypt; this can take some time, but the device can usually be used while decryption runs.
After decryption completes, BitLocker will no longer protect that drive, and the blue BitLocker recovery screen should not appear again for that drive.
- If only “device encryption” is enabled
Some devices use automatic device encryption instead of the full BitLocker UI. In that case:- Open Settings → Update & Security (or Privacy & security on newer Windows) → Device encryption.
- If Device encryption is turned on, turn it Off.
Note: the Settings UI does not show device encryption as enabled until encryption is complete; once turned off, it will not automatically re-enable itself in the future.
- If no BitLocker or device encryption controls appear
If:- Manage BitLocker does not appear in Start search, and
- There is no Device encryption page in Settings,
then the current Windows installation may not have BitLocker/device encryption enabled. In that case, the earlier blue recovery screen likely came from a previous configuration (for example, when the device was managed by an organization). If the device is reimaged or reset, ensure that any organization management or policies that enforce BitLocker are not re-applied.
To avoid future lockouts, always ensure the BitLocker or device encryption recovery key is stored in a safe, accessible location (such as a Microsoft account, Microsoft Entra ID, or another secure backup) before making hardware or firmware changes that might trigger recovery.
References:
- BitLocker overview
- BitLocker Drive Encryption
- BitLocker FAQ
- BitLocker recovery overview
- BitLocker preboot recovery screen
- BitLocker recovery process
- BitLocker recovery: known issues
- I WANT TO FIND MY BITLOCKER RECOVERY KEY FOR MY COMPUTER - Microsoft Q&A I WANT TO FIND MY BITLOCKER RECOVERY KEY FOR MY COMPUTER
- Bitlocker recovery key not working - Microsoft Q&A
- Surface Pro 3 blocked - Microsoft Q&A